NewsTechnology

Let's Encrypt certificates drop from 90 to 64 days on 10 February 2027

Free Let's Encrypt certificates will last 64 days, not 90, from 10 February 2027. Who needs to check their renewals, and when testing starts.

The free security certificates behind the padlock on many websites are about to expire faster. Let’s Encrypt, the non-profit certificate authority, announced on 7 October (US time) that from 10 February 2027, every certificate it issues or renews will last 64 days by default, down from the 90 days it has used since it launched in 2015.

For most Australian websites, nothing should go wrong. Hosting companies and website platforms that use Let’s Encrypt normally renew certificates automatically. But a business that runs its own server, or has a developer’s renewal script set to a fixed schedule, should check it before February. A certificate that isn’t renewed in time makes browsers show a security warning in place of the site.

What is changing

Let’s Encrypt says that on 10 February 2027, all of its subscribers move to 64-day certificates by default, unless they have already chosen one of its shorter options (45 days or 6 days). Any certificate issued or renewed on or after that date is valid for 64 days. Certificates already issued keep their 90-day life, and Let’s Encrypt says it won’t revoke them. It expects the last 90-day certificate to expire on 11 May 2027.

It is also cutting the “authorisation reuse” period, the time after you prove you control a domain during which it will issue certificates without asking you to prove it again, from 30 days to 10 days.

Let’s Encrypt says rate limits won’t change, and neither will its ACME endpoints (the addresses renewal software connects to) or its certificate chains.

The next step is already set

This is the middle step of a longer change. In a December 2025 post, Let’s Encrypt set out its timeline: its default certificates move to 45 days on 16 February 2028, and the authorisation reuse period shrinks to seven hours.

The overall direction is set by industry rules. Let’s Encrypt says its move to 45 days is required by the CA/Browser Forum’s requirements, which all publicly trusted certificate authorities follow. The forum, the group of certificate authorities and browser makers that sets the requirements for publicly trusted certificates, adopted a schedule in 2025 that reduces the maximum validity period from 398 days to 47 days between March 2026 and March 2029. Let’s Encrypt says shorter lifetimes limit the damage when a certificate is issued wrongly or its key is compromised.

That schedule applies to paid certificates as well. Certificate authority DigiCert summarises the steps as a maximum of 200 days from 15 March 2026, 100 days from 15 March 2027 and 47 days from 15 March 2029. On our reading, a business that buys a certificate and installs it by hand will need to do that job several times a year from March 2027, so automation becomes the practical option for paid certificates too.

Who needs to check

If your host or platform manages your certificate, it handles renewals. Our guide to website hosting costs in Australia found that every host we checked includes a free certificate, and that VentraIP and Digital Pacific use Let’s Encrypt. If you’re unsure whether your plan renews automatically, ask your host.

If you or a developer run your own server, check how renewals are scheduled. Let’s Encrypt says renewal software that supports ACME Renewal Information (ARI), which lets Let’s Encrypt tell the software when to renew, “should be all set”. You can check your client’s documentation to see whether it supports ARI.

Renewals hard-coded to a fixed date are the risk. Let’s Encrypt recommends renewing at about two-thirds of the certificate’s lifetime instead, which on our reading is about 42 to 43 days for a 64-day certificate. It suggests searching cron jobs, wrapper scripts and runbooks for common hard-coded numbers such as 83, 80 or 60. A script that renews 80 days after issue, for example, would run after a 64-day certificate had already expired.

If anything in your setup relies on authorisation reuse, the shorter 10-day period may affect it. Let’s Encrypt says most people won’t need to change anything unless their software was specifically designed to rely on it.

Testing starts next week

Let’s Encrypt says it will start issuing 64-day certificates in its staging environment, a test version of the service, on 14 October 2026, and it recommends testing there before the change reaches live certificates. It also suggests using the change to automate reloading and deploying new certificates, and to add alerts for renewal failures.

Checklist

  • Ask your host or web developer who renews your site’s certificate. If it is your hosting plan or website platform, confirm the renewal is automatic.
  • Check whether your renewal software supports ACME Renewal Information (ARI). Let’s Encrypt says clients with ARI should keep renewing on time after 10 February 2027.
  • Search renewal scripts for hard-coded intervals. Look in cron jobs, wrapper scripts and runbooks for numbers such as 83, 80 or 60, and change them to renew at about two-thirds of the certificate’s lifetime.
  • Test against Let’s Encrypt’s staging environment from 14 October 2026. It starts issuing 64-day certificates there on that date.
  • Set up an alert for failed renewals. A certificate that lapses makes browsers warn visitors away from your site.
  • Plan for paid certificates getting shorter. Industry rules cap public certificates at 100 days from 15 March 2027, so ask your certificate provider about automated renewal before then.